ERPNext Penetration Testing
A Frappe method marked allow_guest is reachable by anyone, with no login required. We test your DocType permissions, user permissions and every whitelisted method your instance exposes. CREST-certified testers, fixed price from £2,910 for a 2-day single-instance scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Every API endpoint ERPNext exposes starts as a Python method an admin decided to whitelist, and allow_guest is a separate flag on top of that decision. We test which methods carry that flag and what they let an unauthenticated caller do.
Why an ERPNext finding is a permission decision, not a Frappe flaw
ERPNext’s Role Permissions Manager sets read, write, create, submit, cancel and amend rights per role and per DocType, and Frappe’s own role-based permissions documentation lets that be narrowed further with field-level permission levels. User Permissions sit on top of that and restrict a specific user to their own Customer, Territory or Supplier Group, and the two systems have to agree for a restriction to hold. We test whether they actually do, role by role.
A Web Form’s Login Required setting is off by default, so a form can take anonymous submissions unless an admin switches that on, and Portal Roles decide which menu items and pages a logged-in customer or supplier can reach. Every custom API endpoint starts life as a Python method marked whitelisted, and allow_guest is a separate flag that removes the login requirement from it entirely. We test which whitelisted methods carry that flag and what the code inside them actually lets an unauthenticated caller do.
Server Scripts run inside RestrictedPython on self-hosted instances where an admin has turned the feature on, and Frappe Cloud disables them entirely on shared benches, so what is reachable depends on which of the two you run. Query and Script Reports execute custom Python against your database directly, and API access uses a key and secret pair generated per user rather than a shared credential. We test the reports, custom Frappe apps and API keys your instance actually has, and adjust the infrastructure checks to whether you are on Frappe Cloud or self-hosted.
SCOPE
What we pen test on an ERPNext instance
Role and DocType Permissions
ERPNext’s Role Permissions Manager sets read, write, create, submit, cancel and amend rights per role and per DocType, with field-level permission levels available for finer control. We test whether every role actually holds the rights your business intends, not just the rights it was given when the DocType was created.
User Permissions and Record-Level Restrictions
User Permissions restrict a specific user to their own Customer, Territory or Supplier Group on top of whatever their role already allows, and a gap between the two systems is where a record-level restriction can quietly fail to hold. We test every User Permission against the role permissions it is supposed to narrow.
Public Web Form Submissions
A Web Form’s Login Required setting is off by default, so it can take anonymous public submissions unless an admin switches it on, and the fields exposed on that form are whatever the underlying DocType allows through it. We test which of your web forms accept anonymous submissions and whether any expose more than the public page shows.
Portal Roles and Menu Visibility
Portal Roles decide which menu items and pages a logged-in customer or supplier can reach, with Customer and Supplier contacts auto-assigned by matching Contact email. We test whether a portal user can reach a page or menu item their assigned role was not meant to expose.
Whitelisted Server Methods
Every custom API endpoint in ERPNext starts as a Python method explicitly marked whitelisted, and each one is only as safe as the permission checks written inside it. We test every whitelisted method your instance exposes for what it actually lets a caller do, not just whether it exists.
allow_guest Endpoints
The allow_guest flag on a whitelisted method or an API-type Server Script removes the login requirement entirely, so the method has to enforce its own access control with no session to rely on. We test every allow_guest endpoint for what an unauthenticated caller can read, write or trigger.
Server Scripts and Custom Frappe Apps
Server Scripts run inside RestrictedPython on self-hosted instances where an admin has enabled them, and Frappe Cloud disables the feature entirely on shared benches. We test which Server Scripts and custom Frappe apps your instance runs, and what access they hold beyond the standard role and DocType checks.
Query and Script Reports
A Query or Script Report can run custom Python and SQL directly against your database rather than going through the standard DocType permission layer. We test which reports your instance exposes and whether any return data a viewer’s role and User Permissions should have kept out of reach.
API Key and Secret Handling
REST API access uses a key and secret pair generated per user under their own API Access settings, and every request made with that pair is checked against that user’s role and User Permissions. We test how those pairs are issued, stored and scoped, and what a leaked pair would actually expose.
Frappe Cloud vs Self-Hosted Configuration
Frappe Cloud isolates each site with network-level firewalling and manages framework updates for you, while a self-hosted or private-bench instance leaves those responsibilities, along with whether Server Scripts are even enabled, with your own team. We test the application layer the same way either way, and adjust the infrastructure checks to whichever hosting model you run.
OUR PROCESS
ERPNext Penetration Testing: From Scope to Attestation
Scope and Access
We agree the URL, a System Manager or admin account, and a regular user account for each role and User Permission combination in scope, plus which custom apps, Server Scripts and web forms are included.
Permission and Endpoint Mapping
We map DocType permissions, User Permissions, whitelisted methods and allow_guest endpoints across your instance before manual testing starts.
Manual Testing
A CREST-certified tester manually tests role and DocType boundaries, User Permission enforcement, whitelisted and allow_guest endpoints, and any custom Server Scripts or reports, chaining findings where they compound.
Attestation and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST ERPNext pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent ERPNext Penetration Testing Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 5 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote5 to 7 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test ERPNext For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From ERPNext Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our ERPNext instance?
We need a System Manager or admin account, plus at least one regular user account for each role and User Permission combination you use, so we can test what each level can actually reach. If you run custom Frappe apps or Server Scripts, tell us during scoping so we can agree whether they are in scope.
Will testing touch our live data?
We test whichever environment you give us access to. If that is production, we agree exclusions upfront, such as outbound emails and payment integrations, and we do not run destructive tests against real records without that agreement in writing.
How long does an ERPNext penetration test take?
A single ERPNext instance sits in our 2-day single-instance scope, with a report typically landing around 5 working days after kickoff. An instance with several custom apps, a large whitelisted API surface or multiple portal roles can move into a wider scope.
Do you test Frappe Cloud as well as self-hosted ERPNext?
Yes. We test ERPNext whether it runs on Frappe Cloud, a private bench, or your own self-hosted server. Server Scripts are disabled on Frappe Cloud’s shared benches by default, so we adjust that part of testing to whichever hosting model your instance actually uses.
What is out of scope for a single-instance ERPNext test?
Infrastructure-level issues in the underlying server, network or cloud configuration below ERPNext itself are out of scope for this test and covered by our cloud penetration testing service instead. A separate system that only happens to integrate through the REST API is scoped and quoted separately.
Do you need our source code?
No. Testing is black-box against the running instance by default. A grey-box option, where we review your DocType permission rules, whitelisted methods and Server Scripts alongside testing, is available if you want deeper coverage of specific findings.
Does Frappe or ERPNext have a customer penetration-testing policy we need to follow?
Frappe publishes a responsible-disclosure policy for researchers reporting vulnerabilities in its own products, which is a different process from a customer testing their own ERPNext instance. We confirm Frappe’s and, where relevant, Frappe Cloud’s current terms during scoping before testing starts.
Are allow_guest methods and public web forms included by default?
Yes. Any method marked whitelisted with allow_guest set, and any web form with Login Required switched off, is in scope for a single-instance test unless you tell us to exclude it during scoping.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your ERPNext instance
A Frappe method marked allow_guest is reachable by anyone, with no login required. We test your DocType permissions, user permissions and every whitelisted method your instance exposes. CREST-certified testers, fixed price from £2,910 for a 2-day single-instance scope, quoted within 24 hours.



